13.05.2016 Views

THE HISTORY OF THE DARKSEOUL GROUP AND THE SONY INTRUSION MALWARE DESTOVER

001398694

001398694

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Since we know the XOR key used, we can also translate any other IP’s associated with these domains to presumably<br />

correct C&C IP addresses (see appendix). If we repeat this process with the other XOR key we know of -<br />

0x1AB9C2D8 - we end up with the localhost IP 127.0.0.1 translating to the bogus IP of 167.194.185.27. No<br />

additional data was found at this time using this method, but any DynDNS domain resolving to this IP in the future<br />

might be interesting to look at.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!